{"Entry":{"collection":"guc","key":"oauth_validator_libraries","name":"oauth_validator_libraries","aliases":[],"metadata":{"baseline":false,"boot_human":"Not specified","boot_val":null,"category":"Connections and Authentication / Authentication","category_zh":"","changed_in":[],"changes":[{"documentation_changed":false,"fields":{},"from":"17","status":"added","to":"18"},{"documentation_changed":true,"fields":{},"from":"18","status":"changed","to":"19"}],"content_hash":"4f07113f6c0261633642f7c393e9a0c53b537fd870a72228ee8b464ea793b54a","context":"","default_changed_in":[],"default_history":[{"from":"18","to":"19","value":"Empty string"}],"editorial":{"advice":{"olap":"Use the same validator trust policy for analytical access. If a different issuer or claim mapping is required, list the reviewed modules explicitly and select the intended validator in every matching HBA record.","oltp":"Install one reviewed validator first, pin its package/version on every failover target, and test issuer, audience, expiry, revocation, role mapping, malformed tokens, and identity-provider outage before enabling an oauth HBA rule.","small":"The empty value securely disables OAuth but is not a working OAuth configuration. On a small node, prefer one well-tested validator and budget its token-validation latency instead of weakening checks."},"mechanism":["oauth_validator_libraries lists trusted server modules that can validate OAuth 2.0 bearer tokens. PostgreSQL 18 ships no validator implementation, and the empty default refuses all OAuth connections; a usable deployment must install and name at least one compatible module.","With exactly one listed library, PostgreSQL uses it by default for OAuth connections. With multiple libraries, every oauth record in pg_hba.conf must name a validator selected from this list. The setting has SIGHUP context, so changing the allow-list requires a configuration reload and affects subsequent authentication attempts.","A validator executes trusted native code inside the server authentication path. Its token issuer, audience, claim-to-role mapping, failure behavior, dependencies, package version, and availability on every primary/failover node must agree with pg_hba.conf and the identity provider."],"pitfalls":["Creating an oauth HBA rule while the list is empty; PostgreSQL will refuse every OAuth connection.","Expecting PostgreSQL to provide a built-in validator implementation.","Listing multiple libraries without selecting a validator in every oauth HBA record.","Installing a validator on the primary but not on a failover target, or trusting native code whose issuer, audience, and role mapping were not reviewed."],"references":[{"title":"PostgreSQL 19 Beta 4: oauth_validator_libraries","url":"https://www.postgresql.org/docs/19/runtime-config-connection.html#GUC-OAUTH-VALIDATOR-LIBRARIES"},{"title":"PostgreSQL 19 release notes","url":"https://www.postgresql.org/docs/19/release-19.html"}],"related":["password_encryption","scram_iterations","md5_password_warnings","authentication_timeout","krb_server_keyfile"],"summary":"oauth_validator_libraries is the PostgreSQL setting that lists libraries that may be called to validate OAuth v2 bearer tokens."},"enumvals":[],"first_version":"18","group":"Connections and Authentication","group_slug":"connection","imported_at":"2026-09-27T17:57:31.797369+08:00","intro_commit":{"authored_at":"2025-02-20T16:25:17+01:00","discussion":["https://postgr.es/m/d1b467a78e0e36ed85a09adf979d04cf124a9d4b.camel@vmware.com"],"hash":"b3f0be788afc17d2206e1ae1c731d8aeda1f2f59","subject":"Add support for OAUTHBEARER SASL mechanism","url":"https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=b3f0be788afc17d2206e1ae1c731d8aeda1f2f59"},"key":"oauth_validator_libraries","last_version":"20","max_val":"","min_val":"","name":"oauth_validator_libraries","position":302,"present_in":["18","19","20"],"short_desc":"The library/libraries to use for validating OAuth connection tokens.","short_desc_zh":"","source_rev":"english-manuals:c0c4d53e47baacf47d76bdfdb7ee132b8c67cbef8969029455404141c929303e","unit":"","vartype":"string"}},"Definition":{"Collection":"guc","Key":"oauth_validator_libraries","SourceDatabase":"center","Version":"18","SourceTable":"guc","SourceKey":"oauth_validator_libraries","SourceRevision":"english-manuals:c0c4d53e47baacf47d76bdfdb7ee132b8c67cbef8969029455404141c929303e","Facts":{"boot_val":"","category":"Connections and Authentication / Authentication","context":"sighup","description":"The library/libraries to use for validating OAuth connection tokens. If only one validator library is provided, it will be used by default for any OAuth connections; otherwise, all oauth HBA entries must explicitly set a validator chosen from this list. If set to an empty string (the default), OAuth connections will be refused. This parameter can only be set in the postgresql.conf file. Validator modules must be implemented/obtained separately; PostgreSQL does not ship with any default implementations. For more information on implementing OAuth validators, see Chapter 50.","doc":{"anchor":"GUC-OAUTH-VALIDATOR-LIBRARIES","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"},"documented":true,"enumvals":null,"extra_desc":null,"lang":"en","max_val":null,"metadata_version":"18","min_val":null,"name":"oauth_validator_libraries","short_desc":"Lists libraries that may be called to validate OAuth v2 bearer tokens.","source":"pg-settings-source-snapshot","unit":null,"vartype":"string"},"ManualEvidence":{"doc":{"anchor":"GUC-OAUTH-VALIDATOR-LIBRARIES","file":"runtime-config-connection.html","lang":"en","sha256":"567ba928f3e4c4783f548dc8a54f1e748f02bbe163924605f2132eb5b0da440d","slug":"18"}},"MeasuredEvidence":{"metadata_version":"18"}},"Text":{"Collection":"guc","Key":"oauth_validator_libraries","SourceDatabase":"pgweb","Version":"18","Locale":"zh-Hans","Title":"oauth_validator_libraries","Summary":"","BodyHTML":"\u003cp\u003e用于验证 OAuth 连接令牌的库。如果只提供一个验证器库，它将默认用于任何 OAuth 连接；否则，所有\u003ca href=\"/docs/18/auth-oauth.html\" rel=\"nofollow\"\u003e\u003ccode\u003eoauth\u003c/code\u003e HBA 条目\u003c/a\u003e都必须显式设置一个从该列表中选取的\u003ccode\u003evalidator\u003c/code\u003e。如果设置为空字符串（默认值），OAuth 连接将被拒绝。此参数只能在\u003ccode\u003epostgresql.conf\u003c/code\u003e 文件中设置。\u003c/p\u003e\u003cp\u003e验证器模块必须单独实现或获取；\u003cspan\u003ePostgreSQL\u003c/span\u003e 不提供任何默认实现。关于实现 OAuth 验证器的更多信息，请参见\u003ca href=\"/docs/18/oauth-validators.html\" rel=\"nofollow\"\u003e第 50 章\u003c/a\u003e。\u003c/p\u003e","SourceRevision":"2026-09-11@29c86d9","ContentHash":"7d3f9e96ccd6a0b7f9ce82393efc89598bff6b65f78295c5162bb2a475e14f0b","Payload":{"carried_from":"","carry_reason":"","doc_html":"\u003cp\u003e用于验证 OAuth 连接令牌的库。如果只提供一个验证器库，它将默认用于任何 OAuth 连接；否则，所有\u003ca href=\"/docs/18/auth-oauth.html\" title=\"20.15. OAuth 授权/认证\"\u003e\u003ccode class=\"literal\"\u003eoauth\u003c/code\u003e HBA 条目\u003c/a\u003e都必须显式设置一个从该列表中选取的\u003ccode class=\"literal\"\u003evalidator\u003c/code\u003e。如果设置为空字符串（默认值），OAuth 连接将被拒绝。此参数只能在\u003ccode class=\"filename\"\u003epostgresql.conf\u003c/code\u003e 文件中设置。\u003c/p\u003e\u003cp\u003e验证器模块必须单独实现或获取；\u003cspan class=\"productname\"\u003ePostgreSQL\u003c/span\u003e 不提供任何默认实现。关于实现 OAuth 验证器的更多信息，请参见\u003ca href=\"/docs/18/oauth-validators.html\" title=\"第 50 章 OAuth 验证器模块\"\u003e第 50 章\u003c/a\u003e。\u003c/p\u003e","doc_same_as":""}},"RequestedLocale":"zh-Hans","Fallback":false,"Versions":["18","19","20"],"Locales":["en","zh-Hans"],"Signatures":null,"Spellings":null,"SQLState":null,"Evidence":null}
